4.6
CVSSv2

CVE-2001-0787

Published: 18/10/2001 Updated: 10/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

LPRng in Red Hat Linux 7.0 and 7.1 does not properly drop memberships in supplemental groups when lowering privileges, which could allow a local user to elevate privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat linux 7.1

redhat linux 7.0

Exploits

/* source: wwwsecurityfocuscom/bid/2865/info The LPRng software is an enhanced, extended, and portable implementation of the Berkeley LPR print spooler functionality When the LPRng daemon is initialized, it fails to drop its supplementary groups As a result, the daemon and any child processes it spawns will maintain the supplementary g ...